New Attack on Threefish

February 7th, 2010 admin

At FSE 2010 this week, Dmitry Khovratovich and Ivica Nikolic presented a paper where they cryptanalyze ARX algorithms (algorithms that use only addition, rotation, and exclusive-OR operations): “Rotational Cryptanalysis of ARX.” In the paper, they demonstrate their attack against Threefish. Their attack breaks 39 (out of 72) rounds of Threefish-256 with a complexity of 2252.4, 42 (out of 72) rounds…


Originally posted on Schneier

 
  Related Posts
Man-in-the-Middle Attack Against Chip and PIN
Nice attack against the EMV — Eurocard Mastercard Visa — the “chip and PIN” credit card payment system. The attack allows a criminal to use a stolen card without knowing the PIN. The flaw is that when you put a card into a terminal, a negotiation takes place about how the cardholder should be authenticated: using a PIN, using... 
New Windows Attack
It’s still only in the lab, but nothing detects it right now: The attack is a clever “bait-and-switch” style move. Harmless code is passed to the security software for scanning, but as soon as it’s given the green light, it’s swapped for the malicious code. The attack works even more reliably on multi-core systems because... 
De-Anonymizing Social Network Users
Interesting paper: “A Practical Attack to De-Anonymize Social Network Users.” Abstract. Social networking sites such as Facebook, LinkedIn, and Xing have been reporting exponential growth rates. These sites have millions of registered users, and they are interesting from a security and privacy point of view because they store large amounts... 
U.S. Pinpoints Coder Behind Google Attack
U.S. Pinpoints Coder Behind Google Attack
BEIJING (Reuters) – U.S. government analysts believe a Chinese man with government links wrote the key part of a spyware program used in hacker attacks on Google last year, the Financial Times reported on Monday. The man, a security consultant in his 30s, posted sections of the program to a hacking forum where he described it as something... 
Man-in-the-Middle Attacks Against SSL
Says Matt Blaze: A decade ago, I observed that commercial certificate authorities protect you from anyone from whom they are unwilling to take money. That turns out to be wrong; they don’t even do that much. Scary research by Christopher Soghoian and Sid Stamm: Abstract: This paper introduces a new attack, the compelled certificate creation... 
Google Reports Sophisticated, Targeted Attack From China
Google says an attack originating from China targeted its infrastructure and at least 20 others and was a “highly sophisticated and targeted attack”, apparently to gain access to the e-mail accounts of Chinese human rights activists. From CNN – “Based on our investigation to date we believe their attack did not achieve that... 
Makeup to Fool Face Recognition Software
An NYU student has been reverse-engineering facial recognition algorithms to devise makeup patterns to confuse face recognition software….  Read More →
79% Say Another Terror Attack Likely Within Year
A Nigerian Muslim’s attempt to blow up an airliner landing in Detroit on Christmas Day has Americans much more concerned about the dangers of another terrorist attack. A new Rasmussen Reports national telephone survey finds that 79% of U.S. voters now think it is likely there will be another terrorist attack in the United States in This story... 
Guilty Plea in ‘Anonymous’ DDoS Scientology Attack
A Nebraska man is pleading guilty in federal court to a computer-disruption charge for his role in the 2008 distributed denial-of-service attack that temporarily shuttered Church of Scientology websites, the authorities said Tuesday. Los Angeles federal prosecutors said Brian Thomas Mettenbrink, 20, signed a plea agreement Friday admitting his role... 
Taliban Terror Attack On Hotel Thwarted
Authorities arrested six suspected Taliban militants Monday with a suicide vest and hand grenades allegedly on their way to attack a five-star hotel in Lahore, Pakistan’s cultural capital, police said. Pakistan police have arrested six suspected Taliban militants with a suicide vest and hand grenades allegedly on their way to attack a five-star... 
  Related Tweets from Twitter
re5et (re5et)  : aaaahahhaah http://www.schneier.com/blog/archives/2010/07/pork-filled_cou.html..
Updated : 2010-07-31T05:27:10Z   |  Reply  |  View Tweet
technomancy (Phil Hagelberg)  : Pork bomb! http://www.schneier.com/blog/archives/2010/07/pork-filled_cou.html..
Updated : 2010-07-31T05:24:34Z   |  Reply  |  View Tweet
wood_lam (wood lam)  : Schneier has a post about WikiLeaks: http://www.schneier.com/blog/archives/2010/06/wikileaks.html..
Updated : 2010-07-31T04:17:48Z   |  Reply  |  View Tweet
lifeasdaddy (Bob Meade)  : Powers that be want you to have smart electricity meters in your house. But what about the devastating security hole? http://bit.ly/c2iqfn..
Updated : 2010-07-31T01:44:48Z   |  Reply  |  View Tweet
sambowne (Sam Bowne)  : @mrdomino @sciencequiche SHA-1 collisions have been found http://tinyurl.com/4bmcc..
Updated : 2010-07-31T01:24:18Z   |  Reply  |  View Tweet
  Related News from Digg
No comments yet.
You must be logged in to post a comment.
TOP